Debian

Debian Linux

9174 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Published 05.02.2020 14:15:11
  • Last modified 21.11.2024 05:33:40

It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especial...

  • EPSS 0.12%
  • Published 05.02.2020 14:15:11
  • Last modified 21.11.2024 05:39:09

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

  • EPSS 0.14%
  • Published 05.02.2020 14:15:11
  • Last modified 21.11.2024 05:39:09

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

  • EPSS 20.52%
  • Published 04.02.2020 21:15:10
  • Last modified 21.11.2024 04:23:02

An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

  • EPSS 3.29%
  • Published 04.02.2020 20:15:14
  • Last modified 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • EPSS 43.09%
  • Published 04.02.2020 20:15:14
  • Last modified 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

  • EPSS 63.74%
  • Published 03.02.2020 23:15:11
  • Last modified 21.11.2024 05:39:05

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

  • EPSS 0.97%
  • Published 02.02.2020 14:15:10
  • Last modified 21.11.2024 04:38:30

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows expon...

Exploit
  • EPSS 3.25%
  • Published 30.01.2020 19:15:12
  • Last modified 21.11.2024 05:38:56

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicA...

Exploit
  • EPSS 4.17%
  • Published 29.01.2020 21:15:11
  • Last modified 01.07.2025 18:15:23

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."